34 lines
1.5 KiB
Bash
Executable File
34 lines
1.5 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# Prepare private ARI/HTTP config for the native nonproduction user service.
|
|
# Does not change the service state; restart only after confirming zero calls.
|
|
set -euo pipefail
|
|
|
|
config="$HOME/.config/go-sip-asterisk"
|
|
[[ -d "$config" && -r "$config/asterisk.conf" ]] || { echo 'user Asterisk config missing; fail-closed' >&2; exit 1; }
|
|
for name in ari.conf http.conf ari-secret; do
|
|
[[ ! -e "$config/$name" && ! -L "$config/$name" ]] || { echo "$name already exists; refusing to overwrite" >&2; exit 1; }
|
|
done
|
|
umask 077
|
|
stage="$(mktemp -d "$config/.ari-setup.XXXXXXXX")"
|
|
cleanup() {
|
|
rm -f -- "$stage/ari.conf" "$stage/http.conf" "$stage/ari-secret"
|
|
rmdir -- "$stage"
|
|
}
|
|
trap cleanup EXIT
|
|
secret="$(openssl rand -hex 32)"
|
|
[[ "$secret" =~ ^[0-9a-f]{64}$ ]] || { echo 'could not generate ARI credential' >&2; exit 1; }
|
|
printf '%s' "$secret" >"$stage/ari-secret"
|
|
printf '[general]\nenabled = yes\npretty = no\n\n[go-sip-agent]\ntype = user\nread_only = no\npassword = %s\npassword_format = plain\n' "$secret" >"$stage/ari.conf"
|
|
printf '[general]\nenabled = yes\nbindaddr = 127.0.0.1\nbindport = 8088\n' >"$stage/http.conf"
|
|
|
|
created=()
|
|
for name in ari-secret ari.conf http.conf; do
|
|
if ! ln -- "$stage/$name" "$config/$name"; then
|
|
for own_file in "${created[@]}"; do rm -f -- "$config/$own_file"; done
|
|
echo "cannot create $name without overwriting another file; fail-closed" >&2
|
|
exit 1
|
|
fi
|
|
created+=("$name")
|
|
done
|
|
echo 'private Asterisk ARI/HTTP configuration created; service not restarted'
|